Legal
Privacy policy
How Chersus collects, processes, and protects personal data: what we collect, why, retention, your rights, and who to contact.
Last updated
Chersus operates the Chersus website and the Chersus API. This policy explains what personal data we process, why, and what rights you have. Our company details and contact addresses are in the imprint.
Who we are
Chersus is a product of GoodFolk B.V., a company incorporated in the Netherlands, which operates the Chersus website and the Chersus API. GoodFolk B.V. is the controller for the personal data described in this policy.
Where we process content submitted to the API on behalf of a customer, that customer is the controller and Chersus is the processor. That processing is governed by the data processing addendum; this policy covers Chersus as controller only.
What data we collect
Account data. Your email address, which is all that registration requires, and any profile or billing details you add.
Authentication data. One-time sign-in codes, which expire after five minutes, and session records for the dashboard.
API metadata. API keys, request timestamps, the region that served a request, service and version identifiers, character counts, billing quantities, and trace identifiers. Audit traces returned with a response contain SHA-256 hashes of payloads, never the payloads themselves. We store no audit traces and no payload content.
Billing data. Invoices, payment status, and payment references. If you pay for the service, card and bank data are processed by our payment provider; we do not store payment credentials.
Support data. Anything you send us by email or in writing.
Technical data. Connection data such as IP address, user agent, and time of request, processed by our infrastructure to deliver the site and API securely.
Why we process your data (purposes and legal basis)
- To operate your account, authenticate you, and serve API requests. Legal basis: performance of our contract with you, Article 6(1)(b) GDPR.
- To bill for the service and keep statutory books and records. Legal basis: performance of contract and legal obligation, Articles 6(1)(b) and (c) GDPR.
- To protect the service against abuse, enforce rate limits, and keep it secure and available. Legal basis: our legitimate interest in a secure and reliable service, Article 6(1)(f) GDPR.
- To answer your questions. Legal basis: performance of contract, or legitimate interest before a contract is formed.
- To comply with the law and assert or defend legal claims. Legal basis: legal obligation or legitimate interest.
We do not process API payloads to train models, to profile you, or for advertising.
How long we keep your data
Payloads. Never stored. Processing is stateless, and audit traces exist only in the response you receive.
Idempotency keys. 24 hours, together with the trace identifier they map to, and no content.
Account data. For the life of the account, then deleted within 30 days of closure.
Billing records. Seven years, as Dutch tax law requires.
Technical and security logs. For brief, fixed periods, no longer than 30 days.
Who we share your data with
Only with processors engaged to run the service, each bound by a data processing agreement: our hosting and database provider, our transactional email provider, and our payment provider. The current list, with roles and locations, is on the subprocessors page.
We share data with authorities only where the law requires it. We do not sell data and share nothing for advertising.
International data transfers
All processing takes place on infrastructure inside the European Union. If a processor were ever to process data outside the EEA, we would rely on an adequacy decision or, failing that, on standard contractual clauses, and record the safeguards on the subprocessors page before the change takes effect.
How we protect your data
Processing is stateless: payloads exist in memory for the duration of a request and are never written to storage. Traffic is encrypted in transit with TLS. Access to production systems is restricted to the personnel who need it, under individual credentials, and logged. Audit traces use hashes instead of content, so nothing in them can be reconstructed. Sign-in uses one-time codes rather than passwords.
Your rights under the GDPR
You may request access to your data and its rectification, erasure, restriction, and portability, and you may object to processing based on legitimate interests. Where consent is the legal basis, you may withdraw it at any time. To exercise a right, write to the contact below. We respond within one month and may ask for proof of identity.
Where we act only as processor for a Chersus customer, direct your request to that customer. We assist our customers in answering such requests.
You may lodge a complaint with a supervisory authority, in particular in the member state of your residence, workplace, or the place of the alleged infringement.
Cookies and tracking
Chersus sets no analytics or advertising cookies. The signed-in dashboard sets strictly necessary session cookies, described in the cookie policy.
Children’s privacy
The service is aimed at professional developers. We do not knowingly process the personal data of children, and registration is open only to persons who can conclude a contract under the terms of service.
Changes to this policy
We publish every change on this page with a new last-updated date. If a change affects processing described here in a material way, we notify account holders by email beforehand.
Contact us and our Data Protection Officer
Write to privacy@chersus.com, or to our data protection officer at dpo@chersus.com. Postal and company details are in the imprint.